Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
@esbuild/linux-arm
Advanced tools
The @esbuild/linux-arm package is a binary package for the esbuild bundler optimized for Linux ARM architecture. Esbuild is an extremely fast JavaScript bundler and minifier. It compiles TypeScript and JavaScript into highly optimized code, significantly reducing the size and improving the performance of web applications. The @esbuild/linux-arm package specifically targets devices running on ARM processors, such as Raspberry Pi, making it an ideal choice for development in ARM-based environments.
JavaScript and TypeScript Bundling
This feature allows you to bundle JavaScript and TypeScript files into a single file. The code sample demonstrates how to bundle an entry file 'app.js' into 'out.js', targeting specific browser versions.
require('esbuild').build({
entryPoints: ['app.js'],
bundle: true,
outfile: 'out.js',
platform: 'browser',
target: ['chrome58', 'firefox57', 'safari11', 'edge16']
}).catch(() => process.exit(1))
Minification
This feature enables the minification of JavaScript files, reducing their size for production. The code sample shows how to minify an entry file 'app.js' into 'out.min.js'.
require('esbuild').build({
entryPoints: ['app.js'],
minify: true,
outfile: 'out.min.js'
}).catch(() => process.exit(1))
CSS Bundling and Minification
Esbuild can also bundle and minify CSS files. This code sample demonstrates bundling and minifying a CSS file 'app.css' into 'out.css'.
require('esbuild').build({
entryPoints: ['app.css'],
bundle: true,\n minify: true,
outfile: 'out.css'
}).catch(() => process.exit(1))
Webpack is a powerful module bundler for JavaScript applications. It offers a wide range of plugins and loaders, allowing for a highly customizable build process. Compared to @esbuild/linux-arm, webpack is more feature-rich but significantly slower in terms of build time.
Rollup is another JavaScript module bundler that focuses on producing smaller bundles by eliminating unused code. It is particularly well-suited for libraries and applications using ES modules. While Rollup offers a simpler configuration and efficient bundling, esbuild outperforms it in terms of speed.
Parcel is a web application bundler that offers out-of-the-box support for many file types without the need for configuration. It provides a fast build time similar to esbuild, but esbuild typically has the edge in performance, especially for larger projects.
This is the Linux ARM binary for esbuild, a JavaScript bundler and minifier. See https://github.com/evanw/esbuild for details.
0.24.2
Fix regression with --define
and import.meta
(#4010, #4012, #4013)
The previous change in version 0.24.1 to use a more expression-like parser for define
values to allow quoted property names introduced a regression that removed the ability to use --define:import.meta=...
. Even though import
is normally a keyword that can't be used as an identifier, ES modules special-case the import.meta
expression to behave like an identifier anyway. This change fixes the regression.
This fix was contributed by @sapphi-red.
FAQs
The Linux ARM binary for esbuild, a JavaScript bundler.
The npm package @esbuild/linux-arm receives a total of 4,642,192 weekly downloads. As such, @esbuild/linux-arm popularity was classified as popular.
We found that @esbuild/linux-arm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.